This day 02:05 06:05 10:06 14:06 18:07 22:07
⚠ exploit status: CVE-2026-33824 · KEV CVE-2026-55040 · KEV CVE-2026-59310 · KEV·R CVE-2026-65400 · KEV CVE-2026-60004 · KEV
High  2026-08-25 18:07Z · last 4h · 19 findings · glm-5.2:cloud

Threat Brief — 2026-08-25 — Six New KEV Entries Demand Immediate Patching

CISA pushed six new actively-exploited vulnerabilities into its KEV catalog today, headlined by a Microsoft IKE Service double-free (CVE-2026-33824KEV) and a Gitea code-injection flaw that lets repo collaborators achieve RCE via malicious Git patches. The remaining four KEV additions span Oracle, Zimbra, and three other products—several with public exploit status. CISA also released a joint red-team SOC assessment advisory offering practical defensive lessons.

Top Items

Themes

KEV acceleration: CISA added six CVEs in a single day, continuing an aggressive KEV expansion pattern. Teams should automate KEV feed ingestion against asset inventories rather than relying on periodic reviews. The Gitea and Microsoft IKE entries both represent broad attack surfaces where exploitation doesn't require privileged starting access.

Identity-adjacent attack surface: A separate industry analysis highlights that attackers are shifting from credential theft to targeting identity-verification and account-recovery workflows—bypassing MFA entirely by exploiting the processes that gate it. This aligns with the broader trend of social-engineering-driven breaches seen across recent healthcare and corporate incidents.

Public exploits · latest from the exploit feed

[remote] Ecava_ntegraXor IGX_16.0.701.10 - RCE 2026-10-01 15:15Z · RSS:exploit-db [webapps] Food-Ordering 1.0 - LFI 2026-10-01 15:15Z · RSS:exploit-db [webapps] WordPress 7.0.2 - Path Travesal 2026-10-01 15:15Z · RSS:exploit-db [webapps] TigerGraph_Community_Edition 4.2.4 - arbitrary file write 2026-10-01 15:15Z · RSS:exploit-db [remote] Teltonika_RutOS 00.07.06.21 - command injection 2026-10-01 15:15Z · RSS:exploit-db [webapps] POMS oretnom23v1.0 - SQLi vulnerabilities 2026-10-01 14:15Z · RSS:exploit-db [webapps] InvoicePlane 1.7.1 - RCE 2026-10-01 14:15Z · RSS:exploit-db [webapps] SuiteCRM 8.10.1 - Authenticated SSRF 2026-10-01 14:15Z · RSS:exploit-db [webapps] Krayin CRM 2.2.4 - IDOR 2026-10-01 14:15Z · RSS:exploit-db [remote] MikroTrick, 7.24, 7.24.2, 7.0.0, 7.23.4, 6.0.0, 6.49.21 - RCE 2026-09-30 15:11Z · RSS:exploit-db